---
title: "Important: #106983 - Hardened access to module-related AJAX routes"
manual: "TYPO3 Core Changelog"
version: "main"
permalink: "https://docs.typo3.org/permalink/changelog:important-106983-1750962567"
source: "Changelog/12.4.x/Important-106983-HardenedAccessToModule-relatedAJAXRoutes.rst"
typo3-version: "12.4.x"
typo3-major: 12
type: "important"
issue: 106983
forge: "https://forge.typo3.org/issues/106983"
tags: ["Backend"]
rendered: "2026-10-08T12:25:00+00:00"
---

# Important: #106983 - Hardened access to module-related AJAX routes {#important-106983-1750962567}

See [forge#106983](https://forge.typo3.org/issues/106983)

## Description {#description}

AJAX routes which are exclusively used in a specific backend module can now be
configured to inherit access from the respective module. A new configuration
option `inheritAccessFromModule` is introduced to control this behavior.
It is already added to several existing AJAX routes shipped by TYPO3 core.

Requests to routes with an appropriate access check in place will result in a
403 response if the current backend user lacks required permissions.

## Example configuration {#example-configuration}

In the following example, the `mymodule_myroute` AJAX route inherits access
checks from the `mymodule` backend module:

**EXT:my_extension/Configuration/Backend/AjaxRoutes.php**

```php
return [
    'mymodule_myroute' => [
        'path' => '/mymodule/myroute',
        'target' => \MyVendor\MyExtension\Controller\MySpecialController::class . '::mySpecialAction',
        'inheritAccessFromModule' => 'mymodule',
    ],
];
```
